Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D141EE3E720C8A5B2631A7487FC67405C18B660B893C8CB8E3DF86BD85A07748AB3457 |
|
CONTENT
ssdeep
|
48:U0X+di/qwXj7CSHLLVKwRg6a+D4wc+DQ+Oq+OB+O0+On+OYq+D7+O7Q+DUV+OUJa:VLj6S1yo6e/+GU |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
93826ce59392ecad |
|
VISUAL
aHash
|
ff000c2c2c0c0000 |
|
VISUAL
dHash
|
3006595959590630 |
|
VISUAL
wHash
|
ff000c7c7c0c0018 |
|
VISUAL
colorHash
|
30000000007 |
|
VISUAL
cropResistant
|
1030303030323230,69691676680c5151,4806595959190630 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 211 techniques to evade detection by security scanners and make reverse engineering more difficult.